SBP TRM: SBP Technology Risk Management (TRM) Framework for Payment Institutions
The SBP Technology Risk Management (TRM) Framework for Payment Institutions is the State Bank of Pakistan's baseline of technology, cyber and fraud-risk requirements for licensed payment institutions. These include EMIs, PSOs and PSPs licensed under the PS&EFT Act 2007. It was issued on 3 October 2025 through PSP&OD Circular No. 04 of 2025. Komply maps it as 111 requirements across five areas.
Last updated · By the Faseel compliance team · Not legal advice
SBP TRM at a glance
- Issued by
- State Bank of Pakistan — Payment Systems Policy & Oversight Department
- Reference
- PSP&OD Circular No. 04 of 2025, dated 3 October 2025
- Applies to
- Payment institutions licensed under the PS&EFT Act 2007: EMIs, PSOs, PSPs and other PIs
- Structure
- Governance (Sec 5), Technology & Cyber Risk (Sec 6), Digital Fraud (Sec 7), Outsourcing (Sec 8), DR & BC (Sec 9), plus pilot/commercial readiness (Annexure I)
- Size
- 111 requirements across 25 sub-areas (as mapped in Komply)
- ISO 27001 overlap
- 89 of 111 requirements map to an ISO/IEC 27001:2022 Annex A control
Who must comply with SBP TRM
Electronic Money Institutions (EMIs)
Wallet and e-money providers licensed by SBP.
Payment System Operators & Providers
PSOs and PSPs running payment rails, gateways and switching.
Pilot and commercial-stage PIs
Annexure I sets readiness requirements for institutions moving from pilot to commercial operations.
What SBP TRM requires
- Board and senior-management oversight of technology risk, with approved policies and an independent technology audit.
- Identity and access management, network security, data security, patch and change management.
- Regular security testing (VAPT) and secure API management.
- Incident response and reporting, threat intelligence, and event monitoring and detection.
- Digital-fraud governance, prevention, detection, response and recovery.
- Outsourcing and technology-service-provider oversight, including SBP's rights in agreements.
- Disaster recovery and business continuity, with periodic DR testing.
SBP TRM domains and control counts
111 controls across 25 areas, as mapped in Komply.
| Domain | Controls |
|---|---|
| Governance — Board & Senior Management | 4 |
| Governance — Policies & Procedures | 6 |
| Governance — Technology Audit | 3 |
| Tech & Cyber — Inventory Management | 3 |
| Tech & Cyber — Identity & Access Management | 8 |
| Tech & Cyber — Network Security | 9 |
| Tech & Cyber — Security Testing | 4 |
| Tech & Cyber — Data Security | 4 |
| Tech & Cyber — Patch & Change Management | 6 |
| Tech & Cyber — Incident Response & Reporting | 4 |
| Tech & Cyber — APIs | 5 |
| Tech & Cyber — Threat Intelligence | 2 |
| Tech & Cyber — Event Monitoring & Detection | 3 |
| Digital Fraud — Governance | 4 |
| Digital Fraud — Prevention | 8 |
| Digital Fraud — Detection, Response & Recovery | 6 |
| Outsourcing — Oversight | 2 |
| Outsourcing — Arrangements | 4 |
| Outsourcing — Agreement (SBP rights) | 3 |
| Outsourcing — Third-Party Risk | 3 |
| DR & BC — System Availability | 1 |
| DR & BC — Business Continuity & DR | 5 |
| DR & BC — DR Testing | 3 |
| Annexure I — Pilot Stage Readiness | 7 |
| Annexure I — Commercial Stage Readiness | 4 |
| Total | 111 |
How SBP TRM maps to ISO 27001
89 of 111 TRM requirements map to ISO/IEC 27001:2022 Annex A, so ISO evidence can be reused. Payment-specific requirements such as fraud management, NADRA verification, SBP reporting and liability stand on their own.
Komply gives payment institutions the full TRM requirement set with ISO 27001 mappings, plus the evidence pack and VAPT your technology audit will ask for. Faseel's pentesters handle the security-testing requirements directly. See how Komply works.
SBP TRM FAQ
What is the SBP TRM Framework?
It is the State Bank of Pakistan's Technology Risk Management Framework for Payment Institutions, issued via PSP&OD Circular No. 04 of 2025 on 3 October 2025. It sets baseline requirements for governance, technology and cyber risk, digital-fraud management, outsourcing, and disaster recovery and business continuity.
Who does SBP TRM apply to?
Payment institutions licensed under the Payment Systems and Electronic Fund Transfers Act 2007. That includes Electronic Money Institutions (EMIs), Payment System Operators (PSOs), Payment Service Providers (PSPs) and other PIs. Implementation is expected to be proportionate to the institution's size, products and complexity.
Does SBP TRM require penetration testing?
Yes. The framework includes security-testing requirements (VAPT) under its Technology & Cyber Risk section, alongside API security, network security and event monitoring. Faseel performs these tests and maps the findings straight into the evidence Komply tracks.
How does SBP TRM relate to ISO 27001?
The two overlap substantially. 89 of the 111 requirements mapped in Komply have an equivalent ISO 27001:2022 Annex A control. Fraud, NADRA verification, SBP reporting and liability requirements are payment-specific and must be handled separately.
What is the compliance deadline for SBP TRM?
The timeline is set in PSP&OD Circular No. 04 of 2025. Check the circular and any follow-up SBP instructions for the date that applies to your licence category, because timelines can differ for new and existing institutions.
How does Komply help with SBP TRM?
Komply ships the full requirement set, drafts the policies, tracks evidence against each requirement, flags gaps, and exports an audit-ready package. Faseel adds the VAPT and technology-audit support.
Do ISO 27001 once. Prove SBP TRM too.
Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.